Evolving the Noise out of InfoSec Using Law Enforcement Paradigms
Offered By: YouTube
Course Description
Overview
Syllabus
Intro
WitFoo Mission
Research Effectively
Detection 1.0 - Event Proan
Detectio Classification
Detection 1.1 - Classification
Detection 1.2 -Triage Part 1: Priority
Suspect Centric Investigations WANTED
Detection 2.0 - Host Analysis
Connecting Facts
New Hypothesis • Using Modus Operandi modeling, events can be connected to produce operational levels of higher level events reducing operational strain. • Plan: Create sets of member types and query flow tools to look for connections between the sets.
What is the right MO?
Not all Gang Murders are Drive-bys
Synthetic MO Candidate Experiment . Check every possible pathway (n factorial) (5,040 for 7 sets)
Detection 3.0 - MO Analysis
30 Bullets = 30 Investigations?
Evidence Board - Link Analysis
New Hypothesis • Using Link Analysis, events can be connected to produce operational levels of higher level events reducing operational strain. . Plan: Connect incidents from 3.0 using Bioinformatics (cytoscape)
4.0 - Link Board (via Cytoscape)
"Cloud of Death" = Noise
Bad Tips
Beta Program
Related Courses
Windows Server 2016 Security FeaturesMicrosoft via edX Detecting and Mitigating Cyber Threats and Attacks
University of Colorado System via Coursera Threat Detection: Planning for a Secure Enterprise
Microsoft via edX Microsoft Professional Capstone : Cybersecurity
Microsoft via edX Cyber Security Operations (Cisco CCNA)
The Open University via FutureLearn